CVE-2025-40810
7.8Siemens · Solid Edge
Siemens Solid Edge contains an out-of-bounds write vulnerability in the way it parses PRT files, which can lead to application crashes or arbitrary code execution.
Executive summary
An out-of-bounds write vulnerability in Siemens Solid Edge allows attackers to potentially execute arbitrary code or crash the application by enticing a user to open a specially crafted PRT file.
Vulnerability
The software contains an out-of-bounds write flaw (CWE-787) triggered during the parsing of malformed PRT files. Successful exploitation requires a local user to open a malicious file, placing this within the context of local, user-assisted interaction.
Business impact
The ability to execute code in the context of the current process poses a significant risk to organizational assets, potentially leading to unauthorized data access or the installation of persistent threats. With a CVSS score of 7.8, this vulnerability is classified as High severity, reflecting the potential for total impact on the confidentiality, integrity, and availability of the local workstation or server environment.
Remediation
Immediate Action: Update Siemens Solid Edge to version V224.0 Update 14 or V225.0 Update 6, respectively, as specified in the official Siemens security advisory.
Proactive Monitoring: Monitor endpoint logs for abnormal application termination events or unexpected child processes spawned by the Solid Edge executable.
Compensating Controls: Implement strict file access policies and ensure that users are educated on the risks of opening PRT files obtained from untrusted or unverified sources.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for remote code execution via file parsing, this vulnerability should be treated with high priority. System administrators must facilitate the immediate deployment of the identified vendor patches to eliminate the underlying memory corruption risk and protect user environments from compromise.